Spyrosoft
Spyrosoft
New

Embedded Penetration Tester

120 - 150 PLN/ godz.B2B
SeniorInne·B2B
#429629·Dodano 3 dni temu·0
Źródło: justjoin.it
Aplikuj teraz

Tech Stack / Keywords

EmbeddedIoT SecurityCryptographycommunication protocolspenetration testingthreat modelingSDLCCybersecurityAI

Firma i stanowisko

Spyrosoft is hiring for an advanced penetration testing role with a strong focus on embedded systems security and IoT cybersecurity solutions.

Wymagania

  • Strong experience in embedded systems, IoT security, or product cybersecurity.
  • Hands-on knowledge of secure boot, firmware protection, code signing, and secure update mechanisms.
  • Deep understanding of cryptography and key management in embedded environments.
  • Experience securing communication protocols and network interfaces in connected devices.
  • Knowledge of IoT authentication, authorization, and cloud security architectures.
  • Experience with threat modeling methodologies such as STRIDE, DREAD, and Attack Trees.
  • Ability to perform security risk assessments aligned with ISO 21434, IEC 62443, ISO 27005.
  • Understanding of common embedded attack vectors like side-channel attacks, fault injection, firmware tampering, replay attacks, and MITM attacks.
  • Experience conducting penetration testing on embedded targets using JTAG, UART, SPI, and I²C interfaces.
  • Experience with fuzz testing communication stacks including CAN, TCP/IP, and MQTT.
  • Understanding of secure SDLC principles, DevSecOps, and cybersecurity lifecycle management.
  • Knowledge of vulnerability management, system hardening, and threat surface reduction strategies.
  • Understanding of GDPR, HIPAA, and data protection requirements for cloud-connected solutions.

Nice to have:

  • Experience in regulated industries such as Automotive, Industrial Automation, Medical Devices.
  • Familiarity with IEC 62304, ISO 27001, NIST Cybersecurity Framework, NIST 8259 (IoT Device Cybersecurity).
  • Professional security certifications such as OSCP, GPEN, CompTIA PenTest.
  • Experience working with Rust-based secure embedded applications.
  • Experience in using AI tools in day-to-day workflow.

Obowiązki

  • Design and implement security architectures for embedded and IoT solutions.
  • Define and maintain secure boot, firmware integrity, code signing, and OTA update strategies.
  • Establish secure device provisioning, onboarding, and lifecycle management processes.
  • Conduct threat modeling, security risk assessments, and security reviews throughout the product lifecycle.
  • Assess and mitigate vulnerabilities across embedded devices, cloud platforms, and communication interfaces.
  • Perform penetration testing, fuzz testing, and vulnerability assessments on embedded targets and IoT ecosystems.
  • Drive secure coding practices and perform security-focused code reviews.
  • Collaborate with development, platform, and cloud teams to integrate security into CI/CD pipelines and development processes.
  • Ensure compliance with applicable cybersecurity standards and regulatory requirements.
  • Support incident response activities, vulnerability remediation, and continuous security improvement initiatives.
  • Manage SBOM creation, maintenance, and software supply chain security activities.

Inne informacje

PRZETWARZANIE DANYCH DLA POTRZEB BIEŻĄCEJ REKRUTACJI

Wyrażam zgodę na przetwarzanie moich danych osobowych zawartych w dokumentach rekrutacyjnych przez Spyrosoft S.A. z siedzibą w Wrocławiu, Plac Nowy Targ 28, dla potrzeb uczestnictwa w procesie rekrutacji prowadzonej przez Administratora.

Jednocześnie oświadczam, że swoje dane podaję dobrowolnie oraz przyjmuję do wiadomości, że Administratorem moich danych osobowych jest Spyrosoft S.A. z siedzibą w Wrocławiu, Plac Nowy Targ 28, odbiorcami moich danych mogą być spółki powiązane z Administratorem tj.: a) spółki dominujące w rozumieniu przepisów art. 4 § 1 pkt 4 ustawy z dnia 15 września 2000 r. Kodeks Spółek Handlowych, b) spółki powiązane w rozumieniu art. przepisów art. 4 § 1 pkt 5 ustawy z dnia 15 września 2000 r. Kodeks Spółek Handlowych, c) spółki powiązane osobowo z Administratorem tj. takie w których osoby pełniące funkcje w organach Administratora dysponują co najmniej 20% głosów lub akcji. jak również Klienci tych spółek lub podmioty świadczące usługi na rzecz Administratora, które mogą występować w roli administratorów jak i podmiotów przetwarzających, oraz iż moje dane są przetwarzane zgodnie z

Spyrosoft

Spyrosoft

188 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz